57,566 vulnerabilities published in 2026
ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /serve
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe
The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una
The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on
The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may g
beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same secur
Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space
openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i
Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any
SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through
Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several i
SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are autom
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN,
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1,
Integer Overflow or Wraparound vulnerability in artraweditor ART (rtengine modules). This vulnerability is associated
Out-of-bounds Read vulnerability in tildearrow furnace (extern/libsndfile-modified/src modules). This vulnerability is
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt
Deserialization of Untrusted Data vulnerability in DTStack chunjun (chunjun-core/src/main/java/com/dtstack/chunjun/util
Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfi
Use After Free vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerabili
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/
Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (Modules/ThirdParty/Expat/src/expat modul
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide (lite
NULL Pointer Dereference vulnerability in taurusxin ncmdump (src/utils modules). This vulnerability is associated with
Out-of-bounds Read vulnerability in rizonesoft Notepad3 (scintilla/oniguruma/src modules). This vulnerability is associ
Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modul
Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). This vulnerability is assoc
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exch
Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript repro
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiS
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to t
A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version
Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterp
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if
Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.This issue affects HYPR Server:
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u
A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or
Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started